When ISO 9001:2015 replaced "preventive action" with risk-based thinking, it changed what quality actually has to do — not react to nonconformities after they happen, but see them coming. The catch is that the standard tells you to think in terms of risk without mandating how, so most teams end up with a risk assessment done once at certification, printed, and never reopened. A risk that isn't tracked, reassessed, and closed isn't being managed — it's being remembered. Quality risk management software turns that static document into a living register where every risk has an owner, a score, and a residual level you can prove came down. You can book a demo to see the lifecycle on your own risks.
Stop Filing Risk Assessments. Start Managing Risk as It Actually Moves.
A living risk register, likelihood-and-impact scoring, FMEA linkage, and residual-risk tracking aligned to ISO 9001:2015 and ISO 31000 — so risk-based thinking is something your QMS does, not a binder it produces.
A Risk Assessment You Don't Revisit Isn't Risk Management
The 2015 revision of ISO 9001 built risk-based thinking into clauses across the whole standard — context, planning, operation, and improvement — precisely so risk wouldn't live in one document off to the side. But without a system to hold it, that's exactly where it lands: a spreadsheet built for the audit, accurate the day it was signed, and steadily drifting out of date as processes change, suppliers shift, and new failure modes appear that nobody goes back to add. The result is a quality function that looks risk-aware on paper and is reactive in practice.
The shift from "preventive action" to risk-based thinking was meant to be more than a wording change. The old preventive-action clause was famously the one most organizations treated as a box to tick, generating little real foresight. Risk-based thinking was supposed to fix that by making the consideration of risk continuous and woven through the QMS. But a mindset embedded in a standard still needs somewhere to live operationally, and when the only place it lives is a static file, the new requirement quietly inherits the same fate as the old one — present in the documentation, absent from daily practice.
The risk register is built for certification and then frozen. Real risk profiles change every time a process, material, or supplier does — and a frozen register silently stops reflecting reality within months.
A risk written down without a named owner and a due date is an observation, not a plan. Treatments that aren't assigned and tracked quietly never happen.
Teams run detailed FMEAs and keep a separate quality risk register, and the two never talk — so the failure modes engineering already identified never make it into the risk the organization is managing.
Without tracking residual risk against the original inherent score, there's no evidence a treatment actually worked — only a note that something was done, which is not the same thing to an auditor or to you.
Five Stages That Turn a Risk From Noticed to Closed
ISO 31000 describes risk management as a continuous cycle, not a one-time exercise. Software is what makes the cycle actually cycle — each stage feeding the next, with nothing dropped between them. Here is what each stage does.
Capture risks from every source — process changes, audits, customer complaints, supplier issues, FMEA outputs — into one register, each with an ID, description, cause, and category so nothing lives in a silo.
Score each risk on likelihood and impact to produce an inherent risk score, and place it on a risk matrix that ranks what to address first — so effort goes to the risks that actually matter, not the loudest ones.
Choose a treatment strategy — avoid, mitigate, transfer, or accept — assign an owner and a due date, and describe the controls being put in place. The risk moves from untreated to a tracked plan.
Re-score the risk after controls to get a residual score, and track it against the inherent score. The gap between the two is your proof of how much the treatment actually reduced the risk.
Bring the live register into management review as required by the standard — open risks, overdue treatments, residual trends — as a current picture rather than a document reconstructed the night before.
Inherent, Treated, Residual — the Three Numbers That Matter
The heart of quality risk management is a simple pair of judgments made rigorous: how likely is this, and how bad if it happens. Multiplying likelihood by impact gives a score, the score sets priority, and the change in score after treatment is the whole point. Software keeps these three numbers honest and visible on every risk.
It's worth remembering what the standard actually means by risk: the effect of uncertainty, which can be negative — a threat — or positive — an opportunity. That framing matters because a risk register built only to catalog threats misses half of what risk-based thinking is for. The same scoring discipline that ranks what could go wrong also surfaces where a process could be improved or a capability extended. A register that captures both is doing the fuller job the standard intends, not just guarding the downside.
Likelihood times impact before any controls are applied — the raw exposure. This is what tells you which risks are worth spending on and which can be accepted as they are.
The chosen strategy and the specific controls that act on the risk — the mitigation, the transfer, the process change. This is where the register turns into action with owners and dates.
Likelihood times impact after controls. A large drop from inherent to residual is evidence the treatment worked; a small one signals the risk needs a different approach.
Most quality systems can tell you what they did about a risk. Very few can tell you whether it worked. Tracking inherent and residual scores side by side turns "we added a control" into "we cut this risk from high to low," which is a fundamentally stronger position — with a customer, with an auditor, and in your own decisions about where to spend next. A treatment that barely moves the residual score is telling you something a checkbox never would.
See Every Risk's Full Lifecycle on One Screen
iFactory holds identification, scoring, treatment, and residual tracking in a single connected register — so risk-based thinking becomes a live operational picture instead of a document that expires the day it's printed.
Not Every Risk Gets Mitigated — and That's the Point
Risk-based thinking isn't about eliminating every risk; it's about making a deliberate, documented decision on each one. ISO 31000 recognizes four treatment strategies, and choosing the right one — and recording why — is what separates managed risk from wishful thinking.
Eliminate the risk by not doing the activity that creates it, or changing the conditions so the risk no longer applies. The strongest option when the exposure outweighs the value.
Reduce likelihood or impact through added controls — the workhorse strategy for risks that can't be avoided and shouldn't just be accepted. Most treatments live here.
Shift the risk to another party through contract, insurance, or supplier agreement. The exposure still exists, but the consequence is borne elsewhere by design.
Retain the risk deliberately because it already meets your acceptance criteria. Not neglect — a recorded decision that this level of risk is tolerable, with a rationale to prove it.
FMEA Feeds the Register — It Doesn't Replace It
FMEA and quality risk management are often treated as the same thing, but they operate at different levels. FMEA is a deep, structured analysis of how a specific product or process can fail; the risk register is the organization-wide view of every risk being managed. The power is in connecting them, so the failure modes an FMEA surfaces don't stay trapped in an engineering spreadsheet.
There's a reason this connection matters more than it might seem. An FMEA can identify a high-priority failure mode, assign it a risk priority number, and recommend an action — and then, because the FMEA is a self-contained document owned by engineering, that finding never enters the organization's broader risk picture. The quality director running management review has no visibility into it; the corrective-action system never picks it up. Linking FMEA outputs into the central register is what closes that loop, so the most rigorous risk analysis you do actually informs the risks you manage rather than sitting in a file that gets revisited once a year.
A line-by-line analysis of failure modes for one product or process, scoring severity, occurrence, and detection to find where design or process is most vulnerable.
The organization-level record where the significant failure modes from every FMEA become tracked risks with owners, treatments, and residual scores alongside all other quality risks.
Risk-Based Thinking Is Universal — the Rigor Required Isn't
ISO 9001:2015 asks every organization to think in terms of risk, but it deliberately doesn't mandate the tools. Sector standards layer formal requirements on top, and a good risk system flexes from a light-touch register to a fully documented, auditable process depending on what you answer to.
IATF 16949 layers formal risk and FMEA expectations on ISO 9001, with the AIAG-VDA methodology and supplier risk in scope.
AS9100 builds in explicit risk management for operational and product-safety risk, where the documented trail is scrutinized closely.
ISO 13485 and ISO 14971 make risk management a formal, mandatory process across the product lifecycle, not an optional overlay.
Under ISO 9001 alone, risk-based thinking can stay proportionate — a lightweight register that satisfies auditors without unnecessary paperwork.
From Static Spreadsheet to Living Register in Weeks
Because the framework is established, there's no long build — only your risk categories, scoring scale, and existing risks to bring in. iFactory maps to how you already assess risk and goes live in phases.
Configure your likelihood and impact scales, risk matrix thresholds, categories, and treatment strategies to match how your organization already defines and rates risk.
Bring your existing risk assessments and FMEAs into the register, assign owners and due dates, and establish the residual-tracking baseline for each open risk.
Run the live cycle across sites, feed new risks in from audits and complaints, and pull the register straight into management review with the connected reporting.
What Quality Teams Ask About Risk Management Software
Make Risk-Based Thinking Something Your QMS Does
iFactory turns your risk assessment into a living register — identified, scored, treated, and tracked to residual — so quality gets ahead of problems instead of documenting them after the fact.







